Security fixes are applied to the latest code on the default branch unless the repository documents additional supported release lines.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting flow when it is available from the repository Security tab. Otherwise, contact the repository owner privately through the project's established communication channel.
Include the affected component, reproduction steps, impact, and any suggested mitigation. Do not include live credentials or personal data. You can expect an acknowledgement within five business days.